{"id":"CVE-2026-98008","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: macb: fix NULL pointer dereference on unbind with fixed-link\n\nWhen the device tree describes a fixed-link and has no \"mdio\" child\nnode, macb_mii_init() returns ear…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: macb: fix NULL pointer dereference on unbind with fixed-link\n\nWhen the device tree describes a fixed-link and has no \"mdio\" child\nnode, macb_mii_init() returns ear…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= d0c3601f2c4e12e7689b0f46ebc17525250ea8c3 < f737d999fcb8f276d77b01ea4c2016ee01dad19b","Linux >= d0c3601f2c4e12e7689b0f46ebc17525250ea8c3 < 5710f6a74f63cbba0e15cd75917234916181c9d4","Linux >= d0c3601f2c4e12e7689b0f46ebc17525250ea8c3 < edb39c7666bb3924da761dfb417db85c1e5d8ad3","Linux >= d0c3601f2c4e12e7689b0f46ebc17525250ea8c3 < 38b6be101006d3e7af972999f45d4f1e8250587a","Linux cafa5942bd2df3d80e3eeb2deb4bc050f7761f3d","Linux c81dcaa9cd0b66816c2ecb6c5df0b6afde9c7da5","Linux 831e19e565b5210930fa183730071f8290c61263","Linux 81db1e52848694761a1aa162ce76198af9964ed8","Linux 19088c5378c9fea54e552d8bc7418a3aa1e06990","Linux >= 5.10.228 < 5.11","Linux >= 5.15.169 < 5.16","Linux >= 6.1.114 < 6.2","Linux >= 6.6.58 < 6.7","Linux >= 6.11.5 < 6.12","Linux 6.12"],"published":"2026-09-25","updated":"2026-09-25","sourceUpdated":"2026-09-25T11:17:29.080","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98008","references":[{"url":"https://git.kernel.org/stable/c/38b6be101006d3e7af972999f45d4f1e8250587a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5710f6a74f63cbba0e15cd75917234916181c9d4","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/edb39c7666bb3924da761dfb417db85c1e5d8ad3","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f737d999fcb8f276d77b01ea4c2016ee01dad19b","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-25T11:06:38.860Z","slug":"CVE-2026-98008","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: macb: fix NULL pointer dereference on unbind with fixed-link\n\nWhen the device tree describes a fixed-link and has no \"mdio\" child\nnode, macb_mii_init() returns early without allocating the MDIO bus,\nleaving bp->mii_bus as NULL.\n\nTwo cleanup paths then dereference this NULL bus:\n\n1. On driver unbind, macb_remove() unconditionally calls\n   mdiobus_unregister(bp->mii_bus), which oopses:\n\n  Unable to handle kernel NULL pointer dereference at virtual address 00000000000004a8\n  pc : mdiobus_unregister+0x14/0xa4\n  lr : macb_remove+0x38/0xa4\n  Call trace:\n   mdiobus_unregister+0x14/0xa4 (P)\n   macb_remove+0x38/0xa4\n   platform_remove+0x20/0x30\n   device_release_driver_internal+0x1c8/0x224\n   unbind_store+0xb4/0xbc\n\n2. On the probe error path in macb_probe(), reached when\n   macb_mii_init() has succeeded but a subsequent step fails, the\n   err_out_unregister_mdio label runs the same unconditional cleanup.\n\nmdiobus_unregister() and mdiobus_free() do not guard against a NULL\nbus, so guard the calls in both macb_remove() and the probe error\npath.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}